Executive brief
Trimble TM4WEB is software used to manage billing and project accounting in construction and professional services. The external bill viewer feature contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts into URL parameters. When a user clicks a crafted link, the injected script executes in their browser, potentially allowing attackers to steal session data, redirect users to phishing sites, or perform actions on behalf of the user.
Technical details
The vulnerability is a reflected cross-site scripting (XSS) flaw in the external bill viewer endpoint of Trimble TM4WEB 21.4.0.4. The vulnerable component fails to properly sanitize or validate arbitrary parameters appended to the URL before rendering them in the HTTP response. The attack vector is network-based and requires user interaction (a victim must click or visit a malicious link). No authentication is required to trigger the XSS payload. An attacker can inject arbitrary HTML and JavaScript through URL parameters, which executes in the context of the victim's browser session. Patches or workarounds may be available through Trimble.
Affected products
- Trimble TM4WEB 21.4.0.4
Timeline
- 2022-09-04: disclosed